Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Scan results for trivy shows potential container vulnerabilities #533

Closed
ainsofs opened this issue Nov 24, 2022 · 1 comment
Closed

Scan results for trivy shows potential container vulnerabilities #533

ainsofs opened this issue Nov 24, 2022 · 1 comment

Comments

@ainsofs
Copy link

ainsofs commented Nov 24, 2022

Codebase
Built-in vanilla Drupal or mounted codebase

Describe your issue
Not sure if this is any concern. I scanned the drupal-php container using trivy tool and it returned these results:

https://trivy.dev/results/?image=wodby/drupal-php

It lists the following vulnerabilities:

@csandanov
Copy link
Member

This scan is not correct, they just look up curl version and assume it's vulnerable when in fact curl is already patched. Please see https://git.alpinelinux.org/aports/tree/main/curl?h=3.15-stable, we install curl from alpine package repositories and you can see there's a list of patches applied there during the package build. The first three CVEs reported are patched, the fourth link just returns not found

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants